What is a CIS benchmark?
A CIS benchmark is a configuration baseline published by the Center for Internet Security defining secure-by-default settings for a specific technology: Windows, Linux, AWS, Kubernetes, databases, browsers. Each benchmark contains hundreds of individually-rated controls grouped by Level 1 (essential security) and Level 2 (defense-in-depth). They are the most widely-referenced configuration security baselines globally.
The longer answer.
CIS benchmarks are developed through community consensus, with security practitioners contributing recommended settings that are then reviewed and ratified by CIS. As of 2025, there are over 100 published benchmarks covering operating systems, cloud platforms, container orchestration, databases, applications, and mobile devices.
Each control in a benchmark includes the recommended setting, the rationale (why this matters), the impact (what changes for users or operators), and audit/remediation procedures. This makes benchmarks usable both as a hardening guide and as an audit reference.
More questions on Fundamentals?
Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.